<  All Posts

Exploitation of Mitel MiCollab Path Traversal Vulnerabilities

Author:
Craig Pepper
Overview

This report covers the active exploitation of two vulnerabilities affecting Mitel MiCollab: CVE-2024-41713 and CVE-2024-55550. These vulnerabilities allow attackers to conduct path traversal attacks, leading to unauthorised access and the potential for administrative actions. Public proof-of-concept (PoC) code has been released, accelerating exploitation attempts.

Affected Systems

Vulnerability Details
  1. CVE-2024-41713 (CVSS 9.8 - Critical)
    • A path traversal vulnerability in the NuPoint Unified Messaging (NPM) component.
    • Exploitation allows unauthenticated attackers to:
      • Access provisioning and system data.
      • Perform unauthorised administrative actions on the MiCollab server.
  2. CVE-2024-55550 (Low Severity)
    • A local file read vulnerability exploitable by authenticated administrators.
    • Limited to non-sensitive system information with no risk of privilege escalation or file modification.

Impact

Exploitation

Exploitation in the wild has been confirmed, linked to the PoC code release on December 5, 2024. Organizations are urged to prioritise remediation.

Mitigation Steps

Recommendations
  1. Immediate Patching: Apply the latest updates to affected Mitel MiCollab installations.
  2. Monitor Network Traffic: Implement intrusion detection systems to identify path traversal activities.
  3. Access Control: Restrict access to Mitel MiCollab administrative interfaces to trusted IPs.
  4. User Awareness: Notify administrators of the risk associated with these vulnerabilities.
  5. Incident Response: Be prepared to respond to potential exploitation attempts.

Organisations utilising Mitel MiCollab must act swiftly to mitigate the risk posed by these vulnerabilities. Failure to address the issue promptly could result in unauthorised access and administrative control by threat actors.

Protecting Digital Health Solutions

Contact Periculo for expert cyber security solutions tailored to the digital health industry.

Subscribe
Stay updated with our newsletter for the latest features and releases.
By subscribing, you agree to our Privacy Policy and consent to receive updates from us.
Thank you! Subscription received.
Oops! Something went wrong. Please try again.